athenahealth Marketplace

General SaaS

athenahealth · General SaaS app marketplaces

Best for: {"Healthcare SaaS vendors serving ambulatory practices","Clinical, administrative, billing, and patient-engagement applications needing athenaOne integration","Interoperability, analytics, and data-extraction products using FHIR, HL7, C-CDA, CDS Hooks, or event notifications"}

Overview

athenahealth Marketplace is an app-store-style healthcare ecosystem for integrated solutions that extend athenahealth products and services. Customers browse solutions by need and submit a Get Started Now form; the selected Marketplace Partner responds directly. athenahealth describes partner onboarding, evaluation, and testing intended to support a turnkey integration experience. Developers can use the public Developer Portal for athenaOne proprietary APIs, FHIR and Certified APIs, interfaces, event notifications, CDS Hooks, data visibility, and related platform resources. Building typically involves registering an account, creating an application, selecting an authorization model and API tier, testing in Preview or sandbox environments, requesting OAuth scopes, and completing production and customer-enablement steps. Marketplace commercial terms and universal rate limits are Not publicly specified.

How to build & ship

  1. 1Register for an athenahealth Developer Portal account.
  2. 2Create an application in the Developer Portal console and select Certified APIs only or one or more non-Certified APIs.
  3. 3Choose 2-legged system authorization or 3-legged user authorization and request the required OAuth scopes.
  4. 4Develop and test in the Preview environment and public sandbox, then complete the applicable production credentialing and customer-authorization steps.
  5. 5Pursue Marketplace Partner distribution and complete athenahealth onboarding, evaluation, and testing for the listing and integration.

Key APIs & SDKs

athenaOne proprietary APIs
FHIR REST APIs
Certified FHIR APIs
CDS Hooks
Event Notifications and subscriptions
Data View and bulk extraction

Authentication & security

  • Primary auth: OAuth 2.0 through an authorization server powered by Okta; registered developers receive client credentials for access tokens.
  • Also supports: 2-legged OAuth with the client-credentials grant for service-to-service applications, 3-legged OAuth with the authorization-code grant for patient-facing and provider-facing Certified API applications, SMART App Launch clinical scopes for FHIR APIs, Single sign-on into athenaOne using a third-party identity provider
  • Security review: Not required
  • athenahealth states that Marketplace solutions are onboarded, evaluated, and tested for integration and customer experience. The public sources reviewed do not specify a complete security checklist, evidence package, audit standard, penetration-testing requirement, or universal pass/fail criteria.
  • athenahealth says Marketplace Partners are onboarded and solutions are evaluated and tested to ensure integration with athenahealth products and services. Public materials do not specify a complete review timeline, checklist, acceptance rubric, or appeal process.
  • Not publicly specified in the reviewed first-party sources.

Monetization

Onboarding
Not publicly specified
Commission
Not publicly specified
Merchant of Record
Not publicly specified

Pros & cons for builders

Pros

  • Broad healthcare workflow coverage across athenaOne, FHIR, Certified APIs, interfaces, CDS Hooks, event notifications, and data services.
  • Public developer documentation provides API guidance, authorization details, sandbox information, onboarding resources, and API references.
  • Marketplace distribution includes a listing page, co-branded marketing resources, automated leads, and stated Partner Success support.

Cons

  • Production access and customer enablement can require practice authorization, solution validation, or a Platform Services contract depending on API usage.
  • Standard Marketplace fees, commissions, merchant-of-record terms, and universal API rate limits are Not publicly specified.
  • Healthcare interoperability, sensitive-data permissions, OAuth scope approval, and multiple API tiers create substantial implementation complexity.

Frequently asked questions

How do I get my app approved on athenahealth Marketplace?

athenahealth says Marketplace Partners are onboarded and solutions are evaluated and tested to ensure integration with athenahealth products and services. Public materials do not specify a complete review timeline, checklist, acceptance rubric, or appeal process.

What authentication does athenahealth Marketplace use?

athenahealth Marketplace apps primarily authenticate with OAuth 2.0 through an authorization server powered by Okta; registered developers receive client credentials for access tokens., also supporting 2-legged OAuth with the client-credentials grant for service-to-service applications, 3-legged OAuth with the authorization-code grant for patient-facing and provider-facing Certified API applications, SMART App Launch clinical scopes for FHIR APIs, Single sign-on into athenaOne using a third-party identity provider.

How is athenahealth Marketplace monetized?

athenahealth Marketplace supports not publicly specified monetization. Typical commission: Not publicly specified. Onboarding fee: Not publicly specified.

Is a security review required to list on athenahealth Marketplace?

No, athenahealth Marketplace does not require a formal security review before listing.